Aevia

Privacy Policy

Last updated 2 October 2026

This policy describes what we collect, why, who else sees it, and what you can ask us to do about it. It is written to be read, not to be survived.

1. Who is responsible

The data controller is Sistemik SpA (RUT 78.493.576-0), Santiago, Chile. Privacy contact: hello@aeviamodeler.ai.

2. What we collect

Account data. Your email address, a hashed password, your display name if you set one, and your plan and subscription status. We need this to give you an account.

Content you create. Your chats, product systems, assessments, comparisons, analyses, reports, workspaces, and any documents you upload to your knowledge base. We store this so the Service works; it is yours.

Connection details. If you connect your own openLCA, we store the connection's name and network details and, for a tunnelled connection, an authentication token for the connector app. We do not store a copy of your database.

Connecting from an AI assistant. If you connect Aevia to an assistant such as Claude or ChatGPT through the MCP connector, we keep a record of each connection: its name, the access tier you approved, the workspace and database it works with, when it was last used, and a hashed form of its access credentials, never the credentials themselves. An assistant that registers itself with us leaves a client record (the application's name and the address it returns you to after sign-in); a record that is never used is deleted after 7 days. When an assistant connects, it also reports the name and version of its own software (for example claude-ai/1.0); we record that, and which of Aevia's built-in playbooks it loads, so we can see which assistants our users work from and which guidance they read. These usage records are deleted after 180 days. When the assistant searches the knowledge library, we also keep the text of each search and whether it found anything, so we can investigate problems with search results; these search records are deleted after 30 days. What the assistant asks Aevia to build or calculate is saved to your workspaces like any other content you create.

Usage and cost records. Per-request records of model, token counts and cost, so we can meter credits and show you what a conversation spent. These are tied to your account.

Technical logs. IP address, user agent, request identifiers, timestamps and errors. Used for security, abuse prevention and debugging.

Diagnostic records of model requests. While Aevia is in early access, we keep a complete record of each request the assistant in the app makes to a language model: what was sent to it (its instructions and the conversation so far) and what it answered. We use these records only to investigate when something goes wrong, and they are deleted after 30 days, or sooner if you delete the chat.

Payment data. Handled by Paddle, not by us. We receive a transaction reference, the amount, and your subscription status. We never see or store your card details.

Where you came from. When you create an account we store on it where the visit that led to it came from: the campaign marker on the link you followed, if it had one (?src= or the usual utm_ parameters), and the hostname of the site that linked you to us, which our pages carry along until you sign up. If you create the account while connecting Aevia to an AI assistant, we also record that, and which assistant it was, by the web address it uses to receive the connection (for example claude.ai). It tells us which channels our users actually come from. We never keep the full address of the referring page — only the hostname — and we do not record any of this for people who do not create an account.

Visit statistics. On these marketing pages we count visits using analytics software we run ourselves, on our own server. It records the page viewed, the site that linked you here, and your browser, operating system, screen size and country. It sets no cookies, does not store your IP address, and cannot follow you to any other website. To count repeat visits within a day it uses a value derived from your IP address and browser that is discarded and re-derived daily, so it cannot be used to recognise you tomorrow. The application itself, once you sign in, is not tracked this way.

We do not use advertising trackers, and there is no third-party analytics or advertising cookie on this website. The statistics above are collected by software running on our own server and are never sent to an analytics company; the marker described earlier is likewise stored only by us.

3. Why we may process it, lawfully

4. Who else processes it

To operate, we send parts of a request to service providers acting on our instructions. Each receives only what its task requires.

We do not sell personal data, and we do not share it for advertising. We may disclose data where legally required, and will tell you unless prohibited.

5. Where your data lives, and transfers

The application and its database are hosted in Germany (EU). Some providers above process data elsewhere, including the United States. Where a transfer leaves the EEA we rely on the European Commission's Standard Contractual Clauses or an equivalent safeguard.

6. How long we keep it

Content you create is yours and stays until you delete it. Everything we keep only to run, secure or fix the Service is kept for a set period and then deleted; the periods are listed here.

7. Your rights

Depending on where you live you may have the right to access, correct, delete, restrict or object to our processing of your personal data, and to receive it in a portable format. Chilean law (Ley 19.628, as amended) and, where it applies to you, the GDPR both give rights of this kind.

To exercise any of them, write to hello@aeviamodeler.ai. We will respond within 30 days. You can also complain to your local data-protection authority.

8. Security

Traffic is encrypted in transit with TLS. Passwords are hashed, never stored in a readable form. Credentials you give us for a third-party service — provider API keys, engine connections — are encrypted at rest. Access to production data is limited to those who need it to operate the Service. Databases are backed up encrypted.

No system is perfectly secure. If a breach affects your personal data we will notify you and the relevant authority as the law requires.

9. Cookies

The application uses cookies and local storage strictly to keep you signed in, to remember interface preferences, and to finish connecting an AI assistant while you confirm your email address (that note is deleted after an hour). There are no advertising or cross-site-tracking cookies, and this marketing website sets no cookies at all.

10. Children

The Service is not directed at children and is not for anyone under 18. We do not knowingly collect their data; if we learn we have, we delete it.

11. Changes

We may update this policy. Material changes are announced by email at least 30 days ahead. The date at the top always reflects the current version.